SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-39428

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).

CRITICAL 9.8EPSS 36.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 36.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
36.45% probability · 98th percentile
CISA KEV
Not listed
Affected
oracle/web applications desktop integrator
Source
secalert_us@oracle.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.